Published 3 August 2026 · Updated 30 August 2026
Healthcare AI cannot be considered secure because it was designed with good intentions. It has to be examined: component by component, permission by permission and incident by incident.
Under an acquisition agreement signed on 3 August 2026, SmartClover acquired PurpleRay — a local-first purple-team ecosystem combining software supply-chain analysis, controlled security experiments, operator education and an evidence-centred orchestration layer.
This is not a detour from our healthcare work. It closes an important gap.
SmartClover's portfolio is already built around inspectable workflows. CerviGuard supports clinician-led cervical-screening operations. TealGuard extends that foundation through a 36-month research, engineering and clinical-validation programme for sovereign multimodal AI in gynecologic oncology. DataGems makes synthetic-data work reviewable, while NIS2COMPASS links cybersecurity activity to structured evidence.
Across these projects, the same questions recur: What runs where? What data moves? Who authorised an action? What evidence supports the conclusion? Who remains accountable?
PurpleRay gives us a controlled environment in which those questions can be tested, not merely documented.
From disconnected tools to a defensible chain
Most organisations do not lack security tools. The break usually appears between them: the approved scope sits in one place, the active test in another, defensive telemetry elsewhere, and the conclusion is reconstructed later.
PurpleRay is designed around this missing chain. Work begins with explicit authority. Tests and observations remain within that boundary. Evidence is recorded as the engagement unfolds, reviewed by named people and carried into reporting and remediation.
Local-first operation matters in healthcare. Network maps, vulnerability findings and test evidence can be nearly as sensitive as clinical information. PurpleRay is intended to keep that material under the operator's control, including in segmented or disconnected environments.
Its laboratory adds a practical education layer. Teams can repeat controlled attack-and-defence scenarios, inspect what their controls actually recorded, and learn without turning a hospital's production environment into a classroom.
The open-source foundation stays open

The PurpleRay SBOM Analyzer is the public foundation: a native desktop application that inventories local software and generates deterministic CycloneDX 1.7 SBOMs. It operates offline by default, never executes files from the selected folder, keeps unsupported or partially parsed artefacts visible, and can compare retained scans. An OSV.dev lookup is available only when the operator explicitly requests it.
For healthcare software, this is basic but consequential. A team cannot reason about vulnerable dependencies, supplier exposure or release drift until it knows what the software contains.
The Analyzer remains open source under the Apache License 2.0. The acquisition does not narrow those rights.
PurpleRay CCC and the controlled laboratory
The commercial layer is separate. PurpleRay Command and Control Center (CCC), the orchestration and evidence workflows, SmartClover-developed integrations, product packaging and laboratory assets form the proprietary PurpleRay product.
This layer is being developed to connect software inventory, defensive observation, threat intelligence, controlled adversary emulation, human review and remediation evidence. The platform is under active development; we will continue to distinguish implemented capability from design intent.
PurpleRay CCC and the proprietary PurpleRay product layer are Copyright © 2026 SmartClover SRL. All rights reserved. Third-party components remain governed by their respective licences.

Why PurpleRay belongs at SmartClover
CerviGuard and TealGuard are designed around clinician control, local and edge processing, traceable workflows and sensitive data boundaries. PurpleRay does not become a clinical function inside those systems. It strengthens the engineering and assurance work around them: software inventory, deployment testing, control validation, reproducible failure analysis and team readiness.
For healthcare customers and research partners, the objective is not another badge or generic security report. It is a defensible answer to four questions:
What was authorised? What happened? What did the system and defenders observe? What changed as a result?
That is PurpleRay's role inside SmartClover: helping us build healthcare AI that can not only be useful, but also challenged, tested and defended.
Explore PurpleRay · Open the SBOM Analyzer · Review SmartClover's healthcare AI portfolio
